All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-configobj | Aug 9, 2023 | Apr 3, 2023 |
| Debian | — | No solution existsUpgrade configobj | May 15, 2025 | Apr 3, 2023 |
| Freebsd | — | Upgrade py310-configobjUpgrade py39-configobjUpgrade py311-configobjUpgrade py38-configobj | Apr 14, 2023 | Apr 9, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade python3-configobj | Jan 10, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade python3-configobj | Feb 11, 2025 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp12 | — | Upgrade python3-configobj | Feb 11, 2025 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade python-configobj | Feb 12, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade python3-configobjUpgrade python2-configobj | Mar 13, 2024 | Apr 3, 2023 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-configobj | Apr 9, 2024 | Apr 3, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 3, 2023 |
| Suse | — | Upgrade python3-configobjUpgrade python-configobj | Aug 23, 2023 | Apr 3, 2023 |
| Ubuntu | — | Upgrade python-configobj (Ubuntu Pro)Upgrade python3-configobjUpgrade python3-configobj (Ubuntu Pro) | Sep 27, 2024 | Apr 3, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub